- | X+9 |
+ X+17 |
+ v2 |
v2 |
diff --git a/docs/tasks/access-application-cluster/access-cluster.md b/docs/tasks/access-application-cluster/access-cluster.md
index 9d218e816f..a8c0abcf89 100644
--- a/docs/tasks/access-application-cluster/access-cluster.md
+++ b/docs/tasks/access-application-cluster/access-cluster.md
@@ -246,6 +246,16 @@ As mentioned above, you use the `kubectl cluster-info` command to retrieve the s
If you haven't specified a name for your port, you don't have to specify *port_name* in the URL.
+By default, the API server proxies to your service using http. To use https, prefix the service name with `https:`:
+`http://`*`kubernetes_master_address`*`/api/v1/namespaces/`*`namespace_name`*`/services/`*`https:service_name:[port_name]`*`/proxy`
+
+The supported formats for the name segment of the URL are:
+
+* `` - proxies to the default or unnamed port using http
+* `:` - proxies to the specified port using http
+* `https::` - proxies to the default or unnamed port using https (note the trailing colon)
+* `https::` - proxies to the specified port using https
+
##### Examples
* To access the Elasticsearch service endpoint `_search?q=user:kimchy`, you would use: `http://104.197.5.247/api/v1/namespaces/kube-system/services/elasticsearch-logging/proxy/_search?q=user:kimchy`
diff --git a/docs/tasks/administer-cluster/encrypt-data.md b/docs/tasks/administer-cluster/encrypt-data.md
index 171eae0075..797c2ae957 100644
--- a/docs/tasks/administer-cluster/encrypt-data.md
+++ b/docs/tasks/administer-cluster/encrypt-data.md
@@ -14,6 +14,8 @@ This page shows how to enable and configure encryption of secret data at rest.
* Kubernetes version 1.7.0 or later is required
+* etcd v3 or later is required
+
* Encryption at rest is alpha in 1.7.0 which means it may change without notice. Users may be required to decrypt their data prior to upgrading to 1.8.0.
{% endcapture %}
diff --git a/docs/tasks/administer-cluster/highly-available-master.md b/docs/tasks/administer-cluster/highly-available-master.md
index f6519fad53..cd7fe85e42 100644
--- a/docs/tasks/administer-cluster/highly-available-master.md
+++ b/docs/tasks/administer-cluster/highly-available-master.md
@@ -154,5 +154,4 @@ To make such deployment secure, communication between etcd instances is authoriz
## Additional reading
-[Automated HA master deployment - design doc](https://git.k8s.io/community/contributors/design-proposals/ha_master.md)
-
+[Automated HA master deployment - design doc](https://git.k8s.io/community/contributors/design-proposals/cluster-lifecycle/ha_master.md)
diff --git a/docs/tasks/administer-cluster/memory-constraint-namespace.md b/docs/tasks/administer-cluster/memory-constraint-namespace.md
index 88b46f555d..c203f2e3d4 100644
--- a/docs/tasks/administer-cluster/memory-constraint-namespace.md
+++ b/docs/tasks/administer-cluster/memory-constraint-namespace.md
@@ -123,7 +123,7 @@ kubectl delete pod constraints-mem-demo --namespace=constraints-mem-example
## Attempt to create a Pod that exceeds the maximum memory constraint
Here's the configuration file for a Pod that has one Container. The Container specifies a
-memory request of 700 MiB and a memory limit of 1.5 GiB.
+memory request of 800 MiB and a memory limit of 1.5 GiB.
{% include code.html language="yaml" file="memory-constraints-pod-2.yaml" ghlink="/docs/tasks/administer-cluster/memory-constraints-pod-2.yaml" %}
diff --git a/docs/tasks/administer-cluster/namespaces.md b/docs/tasks/administer-cluster/namespaces.md
index a19707f238..d8e67b8999 100644
--- a/docs/tasks/administer-cluster/namespaces.md
+++ b/docs/tasks/administer-cluster/namespaces.md
@@ -63,7 +63,7 @@ to define *Hard* resource usage limits that a *Namespace* may consume.
A limit range defines min/max constraints on the amount of resources a single entity can consume in
a *Namespace*.
-See [Admission control: Limit Range](https://git.k8s.io/community/contributors/design-proposals/admission_control_limit_range.md)
+See [Admission control: Limit Range](https://git.k8s.io/community/contributors/design-proposals/resource-management/admission_control_limit_range.md)
A namespace can be in one of two phases:
@@ -236,9 +236,9 @@ Let's create some contents.
```shell
$ kubectl run snowflake --image=kubernetes/serve_hostname --replicas=2
```
-We have just created a deployment whose replica size is 2 that is running the pod called snowflake with a basic container that just serves the hostname.
+We have just created a deployment whose replica size is 2 that is running the pod called snowflake with a basic container that just serves the hostname.
Note that `kubectl run` creates deployments only on Kubernetes cluster >= v1.2. If you are running older versions, it creates replication controllers instead.
-If you want to obtain the old behavior, use `--generator=run/v1` to create replication controllers. See [`kubectl run`](/docs/user-guide/kubectl/v1.7/#run) for more details.
+If you want to obtain the old behavior, use `--generator=run/v1` to create replication controllers. See [`kubectl run`](/docs/user-guide/kubectl/v1.7/#run) for more details.
```shell
$ kubectl get deployment
@@ -322,7 +322,7 @@ The Namespace provides a unique scope for:
2. delegated management authority to trusted users
3. ability to limit community resource consumption
-Use cases include:
+Use cases include:
1. As a cluster operator, I want to support multiple user communities on a single cluster.
2. As a cluster operator, I want to delegate authority to partitions of the cluster to trusted users
diff --git a/docs/tasks/debug-application-cluster/debug-stateful-set.md b/docs/tasks/debug-application-cluster/debug-stateful-set.md
index ed64ffada6..9cfdec1afb 100644
--- a/docs/tasks/debug-application-cluster/debug-stateful-set.md
+++ b/docs/tasks/debug-application-cluster/debug-stateful-set.md
@@ -18,7 +18,6 @@ This task shows you how to debug a StatefulSet.
{% capture prerequisites %}
-
* You need to have a Kubernetes cluster, and the kubectl command-line tool must be configured to communicate with your cluster.
* You should have a StatefulSet running that you want to investigate.
diff --git a/docs/tutorials/stateful-application/basic-stateful-set.md b/docs/tutorials/stateful-application/basic-stateful-set.md
index ac8242f7d8..dc7cfca526 100644
--- a/docs/tutorials/stateful-application/basic-stateful-set.md
+++ b/docs/tutorials/stateful-application/basic-stateful-set.md
@@ -22,14 +22,14 @@ following Kubernetes concepts.
* [Pods](/docs/user-guide/pods/single-container/)
* [Cluster DNS](/docs/concepts/services-networking/dns-pod-service/)
* [Headless Services](/docs/concepts/services-networking/service/#headless-services)
-* [PersistentVolumes](/docs/concepts/storage/volumes/)
+* [PersistentVolumes](/docs/concepts/storage/persistent-volumes/)
* [PersistentVolume Provisioning](https://github.com/kubernetes/examples/tree/{{page.githubbranch}}/staging/persistent-volume-provisioning/)
* [StatefulSets](/docs/concepts/abstractions/controllers/statefulsets/)
* [kubectl CLI](/docs/user-guide/kubectl)
This tutorial assumes that your cluster is configured to dynamically provision
PersistentVolumes. If your cluster is not configured to do so, you
-will have to manually provision five 1 GiB volumes prior to starting this
+will have to manually provision two 1 GiB volumes prior to starting this
tutorial.
{% endcapture %}
@@ -37,7 +37,7 @@ tutorial.
StatefulSets are intended to be used with stateful applications and distributed
systems. However, the administration of stateful applications and
distributed systems on Kubernetes is a broad, complex topic. In order to
-demonstrate the basic features of a StatefulSet, and to not conflate the former
+demonstrate the basic features of a StatefulSet, and not to conflate the former
topic with the latter, you will deploy a simple web application using a StatefulSet.
After this tutorial, you will be familiar with the following.
@@ -262,8 +262,7 @@ www-web-0 Bound pvc-15c268c7-b507-11e6-932f-42010a800002 1Gi RWO
www-web-1 Bound pvc-15c79307-b507-11e6-932f-42010a800002 1Gi RWO 48s
```
The StatefulSet controller created two PersistentVolumeClaims that are
-bound to two [PersistentVolumes](/docs/concepts/storage/volumes/). As the
-cluster used in this tutorial is configured to dynamically provision
+bound to two [PersistentVolumes](/docs/concepts/storage/persistent-volumes/). As the cluster used in this tutorial is configured to dynamically provision
PersistentVolumes, the PersistentVolumes were created and bound automatically.
The NGINX webservers, by default, will serve an index file at
@@ -330,7 +329,7 @@ web-1
Even though `web-0` and `web-1` were rescheduled, they continue to serve their
hostnames because the PersistentVolumes associated with their
-PersistentVolumeClaims are remounted to their `volumeMount`s. No matter what
+PersistentVolumeClaims are remounted to their `volumeMounts`. No matter what
node `web-0`and `web-1` are scheduled on, their PersistentVolumes will be
mounted to the appropriate mount points.
@@ -338,8 +337,7 @@ mounted to the appropriate mount points.
Scaling a StatefulSet refers to increasing or decreasing the number of replicas.
This is accomplished by updating the `replicas` field. You can use either
[`kubectl scale`](/docs/user-guide/kubectl/{{page.version}}/#scale) or
-[`kubectl patch`](/docs/user-guide/kubectl/{{page.version}}/#patch) to scale a Stateful
-Set.
+[`kubectl patch`](/docs/user-guide/kubectl/{{page.version}}/#patch) to scale a StatefulSet.
### Scaling Up
@@ -440,10 +438,7 @@ www-web-4 Bound pvc-e11bb5f8-b508-11e6-932f-42010a800002 1Gi RWO
```
There are still five PersistentVolumeClaims and five PersistentVolumes.
-When exploring a Pod's [stable storage](#stable-storage), we saw that the
-PersistentVolumes mounted to the Pods of a StatefulSet are not deleted when
-the StatefulSet's Pods are deleted. This is still true when Pod deletion is
-caused by scaling the StatefulSet down.
+When exploring a Pod's [stable storage](#writing-to-stable-storage), we saw that the PersistentVolumes mounted to the Pods of a StatefulSet are not deleted whenthe StatefulSet's Pods are deleted. This is still true when Pod deletion is caused by scaling the StatefulSet down.
## Updating StatefulSets
@@ -721,8 +716,7 @@ automatically update Pods when a modification is made to the StatefulSet's
## Deleting StatefulSets
StatefulSet supports both Non-Cascading and Cascading deletion. In a
-Non-Cascading Delete, the StatefulSet's Pods are not deleted when the Stateful
-Set is deleted. In a Cascading Delete, both the StatefulSet and its Pods are
+Non-Cascading Delete, the StatefulSet's Pods are not deleted when the StatefulSet is deleted. In a Cascading Delete, both the StatefulSet and its Pods are
deleted.
### Non-Cascading Delete
@@ -866,7 +860,7 @@ web-1 0/1 Terminating 0 29m
```
-As you saw in the [Scaling Down](#ordered-pod-termination) section, the Pods
+As you saw in the [Scaling Down](#scaling-down) section, the Pods
are terminated one at a time, with respect to the reverse order of their ordinal
indices. Before terminating a Pod, the StatefulSet controller waits for
the Pod's successor to be completely terminated.
diff --git a/docs/user-guide/pod-security-policy/OWNERS.txt b/docs/user-guide/pod-security-policy/OWNERS.txt
deleted file mode 100644
index 8ac19e87e5..0000000000
--- a/docs/user-guide/pod-security-policy/OWNERS.txt
+++ /dev/null
@@ -1,2 +0,0 @@
-approvers:
-- pweil-
diff --git a/docs/user-guide/pod-security-policy/psp.yaml b/docs/user-guide/pod-security-policy/psp.yaml
deleted file mode 100644
index 9f037f67d0..0000000000
--- a/docs/user-guide/pod-security-policy/psp.yaml
+++ /dev/null
@@ -1,18 +0,0 @@
-apiVersion: extensions/v1beta1
-kind: PodSecurityPolicy
-metadata:
- name: permissive
-spec:
- seLinux:
- rule: RunAsAny
- supplementalGroups:
- rule: RunAsAny
- runAsUser:
- rule: RunAsAny
- fsGroup:
- rule: RunAsAny
- hostPorts:
- - min: 8000
- max: 8080
- volumes:
- - '*'
diff --git a/test/examples_test.go b/test/examples_test.go
index ae9664db8c..80d7b83e45 100644
--- a/test/examples_test.go
+++ b/test/examples_test.go
@@ -234,7 +234,7 @@ func TestExampleObjectSchemas(t *testing.T) {
"kitten-rc": {&api.ReplicationController{}},
"nautilus-rc": {&api.ReplicationController{}},
},
- "../docs/user-guide/pod-security-policy": {
+ "../docs/concepts/policy": {
"psp": {&extensions.PodSecurityPolicy{}},
},
"../docs/user-guide/persistent-volumes/volumes": {
|